theHarvester discovery and evidence architecture
An authorized finite run selects passive, DNS, or direct activity, then saves normalized findings with their provenance and producer outcomes for review and export.
THEHARVESTER RUN
From an authorized target to saved evidence
Run selected sources and actions; keep each outcome with the findings.
01 · SCOPE
Define the run
One authorized target
Selected sources
Explicit actions
FINITE · BOUNDED
02 · ACTIVITY
Choose the boundary
P0
Passive collection
public providers / datasets
P1
DNS interaction
authorized names / addresses
P2
Direct interaction
selected target endpoints
03 · EXECUTE
Run and record outcomes
Collect observations
Keep results so far
Record producer outcomes
COMPLETED · PARTIAL · FAILED
RATE-LIMITED · SKIPPED
04 · EVIDENCE
Normalize once
Canonical kind + value
Provenance survives deduplication
Producer outcomes stay attached
COMPLETE · PARTIAL · FAILED
PARTIAL RESULTS
theHarvester keeps results when
one producer stops early.
USE THE SAME EVIDENCE
Review
TERMINAL
HARVESTVIEW
Automate
REST · JSONL
Retain
SQLITE
Integrate
JSON · XML